Proxygen is a lightweight HTTP library and server framework developed by Meta (Facebook) that handles request processing and protocol management in web infrastructure. Its vulnerability profile centers on the access-control, resource-management, and input-handling weaknesses inherent to a protocol-processing component, including improper access control, uncontrolled resource consumption, input-validation gaps, and injection-related flaws. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Proxygen Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-7264CRITICAL The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking and injection attacks. | Apr 10, 2017 | 9.8 | 29 | NO | NO |
CVE-2018-6347HIGH An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior to v2018.12.31.00. | Dec 31, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-6346HIGH A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This affects Proxygen prior to v2018.12.31.00. | Dec 31, 2018 | 7.5 | 24 | NO | NO |
CVE-2015-7265HIGH Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attacks and bypass ACL checks. | Apr 10, 2017 | 7.5 | 19 | NO | NO |
CVE-2015-7263HIGH The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass ACL checks via a crafted host value. | Apr 10, 2017 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Proxygen Project.
Media articles that mention a CVE ID that affects a product developed by Proxygen Project — matched by CVE ID, not by vendor name.